Cisco Certified Support Technician (CCST) NetworkingSecurity FundamentalsMedium

A company requires all its employees to use a combination of a password and a one-time code generated by a mobile application to access internal systems. This measure is implemented to ensure that even if a password is stolen, unauthorized access is still prevented. Which security concept is the company enforcing?

  1. AMulti-factor authentication (MFA)
  2. BAuthorization
  3. CSingle Sign-On (SSO)
  4. DNon-repudiation
Show answer & explanation

Correct answer: A. Multi-factor authentication (MFA)

Multi-factor authentication (MFA) requires users to provide two or more verification factors to gain access to a resource. In this scenario, the 'password' represents 'something you know,' and the 'one-time code generated by a mobile application' represents 'something you have,' fulfilling the MFA requirement.

Why the other options are wrong

  • B. Authorization determines what an authenticated user can do, not how they prove their identity.
  • C. SSO allows a user to log in once to access multiple applications, simplifying login, but not primarily enhancing the authentication strength itself in this manner.
  • D. Non-repudiation ensures that a party cannot deny having performed an action, which is not the primary goal here.

Multi-factor Authentication (MFA)

A security system that requires a user to provide two or more verification factors to gain access to a resource such as an application, online account, or VPN.

  • Combines different types of authentication factors.
  • Common factors: something you know, something you have, something you are.
  • Significantly reduces the risk of unauthorized access.

Memory trick: Authentication factors are how you prove you are who you say you are.

More Security Fundamentals questions